Skip to content

build(deps-dev): bump vitest from 5.0.2 to 5.0.3 - #30

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/vitest-5.0.2
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/vitest-5.0.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown

Bumps vitest from 5.0.2 to 5.0.3.

Release notes

Sourced from vitest's releases.

v5.0.3

   🐞 Bug Fixes

    View changes on GitHub
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
Bumps [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) from 5.0.2 to 5.0.3.
- [Release notes](https://github.com/vitest-dev/vitest/releases)
- [Changelog](https://github.com/vitest-dev/vitest/blob/main/docs/releases.md)
- [Commits](https://github.com/vitest-dev/vitest/commits/v5.0.3/packages/vitest)

---
updated-dependencies:
- dependency-name: vitest
  dependency-version: 5.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps-dev): bump vitest from 5.0.1 to 5.0.2 build(deps-dev): bump vitest from 5.0.2 to 5.0.3 Oct 3, 2026
@dependabot
dependabot Bot force-pushed the dependabot/npm_and_yarn/vitest-5.0.2 branch from f24ee78 to 96daa6f Compare October 3, 2026 22:34
napalm255 added a commit that referenced this pull request Oct 3, 2026
Adopt [quick-template
v0.1.2](https://github.com/Ghost-Assembly/quick-template/releases/tag/v0.1.2),
pinned to `174a20f771bc1b25d19b5547820fa3647c752a1a`, so dependency and
Action updates preserve all 33 canonical files across the fleet.

Updates Vitest/coverage to 5.0.3, ESLint 10.12.0, eslint-plugin-security
4.2.0, globals 17.13.0, Python 3.14.8, uv 0.12.22, Ruff 0.16.10, Trivy
0.75.0, and gh 2.102.0. Node remains on the current 24 LTS patch. Shared
workflows use current SHA-pinned Actions and mise 2026.10.1; CodeQL
init/analyze share the 4.38.2 commit, and mise-action 5.0.1 fixes
cached-binary verification. Dependabot's separate SONAR_TOKEN secret is
configured.

Full local `just ci` passes: 321 JavaScript tests, 29 Python tests, 52
browser tests, security/source/history scans, and byte-for-byte equality
with GNOME's official packer. Template checks confirm the exact merged
canonical payload. Hosted CI, CodeQL, and authenticated Sonar remain
required before merging; the zero-finding and zero-duplication policy is
unchanged.

Supersedes the dependency versions proposed in #32, #31, #30, #29. Those
proposals will be retired only after this complete update passes and
merges. No extension version release or store submission is included.
@dependabot @github

dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Author

Looks like vitest is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 3, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/vitest-5.0.2 branch October 3, 2026 23:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants